{"api_version":"1","generated_at":"2026-07-23T12:45:04+00:00","cve":"CVE-2020-5683","urls":{"html":"https://cve.report/CVE-2020-5683","api":"https://cve.report/api/cve/CVE-2020-5683.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-5683","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-5683"},"summary":{"title":"CVE-2020-5683","description":"Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier allows remote attackers to alter the data by uploading a specially crafted file.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2020-12-16 08:15:00","updated_at":"2020-12-18 14:58:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://github.com/weseek/growi","name":"https://github.com/weseek/growi","refsource":"MISC","tags":["Product","Third Party Advisory"],"title":"GitHub - weseek/growi: GROWI - Team collaboration software using markdown","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://hub.docker.com/r/weseek/growi/","name":"https://hub.docker.com/r/weseek/growi/","refsource":"MISC","tags":["Product","Third Party Advisory"],"title":"Docker Hub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://jvn.jp/en/jp/JVN94169589/index.html","name":"https://jvn.jp/en/jp/JVN94169589/index.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"JVN#94169589: Multiple vulnerabilities in GROWI","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-5683","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5683","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"5683","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"weseek","cpe5":"growi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5683","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"weseek","cpe5":"growi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"5683","vulnerable":"1","versionEndIncluding":"3.8.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"weseek","cpe5":"growi","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-5683","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"WESEEK, Inc.","product":{"product_data":[{"product_name":"GROWI","version":{"version_data":[{"version_value":"GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Directory traversal"}]}]},"references":{"reference_data":[{"url":"https://github.com/weseek/growi","refsource":"MISC","name":"https://github.com/weseek/growi"},{"url":"https://hub.docker.com/r/weseek/growi/","refsource":"MISC","name":"https://hub.docker.com/r/weseek/growi/"},{"url":"https://jvn.jp/en/jp/JVN94169589/index.html","refsource":"MISC","name":"https://jvn.jp/en/jp/JVN94169589/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier allows remote attackers to alter the data by uploading a specially crafted file."}]}},"nvd":{"publishedDate":"2020-12-16 08:15:00","lastModifiedDate":"2020-12-18 14:58:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*","versionEndIncluding":"3.8.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.0","versionEndExcluding":"4.1.12","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2.0","versionEndExcluding":"4.2.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"5683","Ordinal":"165929","Title":"CVE-2020-5683","CVE":"CVE-2020-5683","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"5683","Ordinal":"1","NoteData":"Directory traversal vulnerability in GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier GROWI versions prior to v4.2.3 (v4.2 Series), GROWI versions prior to v4.1.12 (v4.1 Series), and GROWI v3 series and earlier allows remote attackers to alter the data by uploading a specially crafted file.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"5683","Ordinal":"2","NoteData":"2020-12-16","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"5683","Ordinal":"3","NoteData":"2020-12-16","Type":"Other","Title":"Modified"}]}}}